Impact
The vulnerability allows an attacker to obtain arbitrary code execution on a system running the Sentio Creator Device Manager extension by uploading a malicious device driver package. The driver bypasses normal verification controls, enabling attacker‑controlled code to run with the privileges of the local user. Because arbitrary code runs under the context of the process that loads the driver, the impact includes full compromise for the affected system.
Affected Systems
Affected products are SICK AG's Sentio Creator Extension 'Device Manager'. The issue is mitigated by upgrading to version 1.4.1 of the extension; no other version ranges are provided, so all earlier releases are considered vulnerable until the upgrade is applied.
Risk and Exploitability
The CVSS v3.1 score of 8.3 classifies the flaw as high severity. No EPSS score is available, and the vulnerability is not currently listed in the CISA KEV catalog, indicating no widespread exploitation is reported. Exploitation requires user interaction to supply the malicious driver package, so the attack vector is likely local or requires the attacker to persuade a user to load the driver. Given the high severity and potential for system compromise, the risk to environments that rely on the Device Manager is significant.
OpenCVE Enrichment